Live data from Hacker News

Ask HN: How do you start over with 2FA after losing your phone?

news.ycombinator.com

51–60 of 112 posts

Re: Ask HN: How do you start over with 2FA after losing your phone?

#51

You can back up your 2FA codes to another phone, at least Google Authenticator lets you do this. An old phone is the easiest, most convenient way to do this since it has a camera that you can use to scan the code on your main phone. If you don't have the backup codes or the one-time codes, you're going to have a problem and you'll need to contact the services to somehow let you in or take off 2FA. Depending on what t…

BTW this process is broken with small display. I have a very tiny Android phone and to backup the codes I need to scan an QR code on this small display, which isn't working out. The resolution is too small. And there is no other way to backup Google Authenticator I am aware of. So be careful in smaller display, you probably cannot backup Goggle Authenticator.

In developer settings you can change the minimum width. Iirc a larger number makes the UI smaller (tablet style). You can try that if the display is fundamentally large enough. And/or screenshot and zoom in in the gallery. Or use apps like scrpy maybe?

Re: Ask HN: How do you start over with 2FA after losing your phone?

#52

This same thing happened to me with Discord once, I just wrote to them and filed a complaint saying my account got "hacked" and that the hacker changed the 2fa mobile number. With adequate proof and justification I think you should be able to get back your accounts, that is if your service does allow you to get back your account. One tip is to have multiple phones for 2fa and then just not using the other phone, if y…

Why did you decide to lie in your complaint?

Yeah, this is disturbing. He's admitting he used social engineering to get back into his own locked account and he's happy that it worked. Assuming he did this over email / web the "proof" he sent them was probably a photo of driver's license which really doesn't prove ownership of identity when your account was just hacked.

We really need a third party service that allows you to walk up, have some DNA taken, verify you are who you say you are, and then unlock accounts in these cases. We can have the government do it, they have all our DNA anyway!

Re: Ask HN: How do you start over with 2FA after losing your phone?

#53
Funny you should ask - a while ago I had the screen and battery replaced in my phone, so I did a factory wipe.

Little did I know, backing up the Google Authenticator app doesn't preserve the config, so all my codes were gone.

Apparently most services don't mind and will let you disable MFA via email confirmation.

One notable and unlikely exception was OVH - luckily I had backup codes, so I didn't have to present them my id.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#54
post #33

Earlier quoted context omitted.

What? Where the 2FA codes come from isn't relevant, as long as the device (laptop, phone, desktop, hardware) is protected in some way or another (like password). Backup codes come from the service which is 2FA protected anyways, not from the 2FA authenticator itself. Edit: oh, reading your message again, are you referring to SMS-based 2FA? I assumed TOTP 2FA in this submission. If you mean SMS-based 2FA, then yeah I…

Nobody has a secure password on their phone, so your requirement fails. There is no way to get a secure password on a phone as one of the requirements of a phone is quick access, and no fast password is secure. (maybe finger prints, but I have found them unreliable and so I quit using them) If your phone based code system is also available on other accounts, and you can access those other accounts without the phone t…

> Nobody has a secure password on their phone, so your requirement fails. > maybe finger prints, but I have found them unreliable and so I quit using them

You mean that you specifically do not have a secure password on your phone because you chose not to. The rest of us use finger print sensors or facial recognition to make our devices as secure as can be. Your argument applies only to you and a handful of people.

The SMS fallback is always combined with your finger print in all applications I've used.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#56
post #33

Earlier quoted context omitted.

Nobody has a secure password on their phone, so your requirement fails. There is no way to get a secure password on a phone as one of the requirements of a phone is quick access, and no fast password is secure. (maybe finger prints, but I have found them unreliable and so I quit using them) If your phone based code system is also available on other accounts, and you can access those other accounts without the phone t…

> Nobody has a secure password on their phone, so your requirement fails. > maybe finger prints, but I have found them unreliable and so I quit using them You mean that you specifically do not have a secure password on your phone because you chose not to. The rest of us use finger print sensors or facial recognition to make our devices as secure as can be. Your argument applies only to you and a handful of people. Th…

How long is the pin code that can be used to log-in into your phone and likely must be used when you restart it? 4-6 digits?

Re: Ask HN: How do you start over with 2FA after losing your phone?

#57
post #15

Use your backup codes that you've downloaded and safe-kept somewhere (you did this right?). If not, I'm afraid you're out of luck. There are two possible outcomes from contacting support for a service, asking to regain control over a 2FA-protected account, both which sucks, but on different levels. 1. You write them, proving who you are, and they tell you to get lost unless you have the 2FA proper codes, or backup co…

This is why phone based 2fa is not secure and not recommended. Sure it is easy, but it isn't secure in important ways

No, SMS-based 2FA is the security problem due to SIM-swapping attacks.

Loss of a phone with a 2FA authenticator app isn't a security problem, unless one failed to make backups of the 2FA secrets for restauring.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#58
post #33

Earlier quoted context omitted.

Nobody has a secure password on their phone, so your requirement fails. There is no way to get a secure password on a phone as one of the requirements of a phone is quick access, and no fast password is secure. (maybe finger prints, but I have found them unreliable and so I quit using them) If your phone based code system is also available on other accounts, and you can access those other accounts without the phone t…

> Nobody has a secure password on their phone, so your requirement fails. > maybe finger prints, but I have found them unreliable and so I quit using them You mean that you specifically do not have a secure password on your phone because you chose not to. The rest of us use finger print sensors or facial recognition to make our devices as secure as can be. Your argument applies only to you and a handful of people. Th…

Biometric phone security is only secure until a judge or police officer compels you to unlock your phone; and legally you must comply, because your face or finger aren't speech. However, if you use a passphrase, (at least in the US and other countries with string freedom of speech laws) you can't be legally compelled to unlock the phone, as that would impinge on freedom of speech.

I never use biometrics to unlock my phone or computer for that reason.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#59
post #58

Earlier quoted context omitted.

> Nobody has a secure password on their phone, so your requirement fails. > maybe finger prints, but I have found them unreliable and so I quit using them You mean that you specifically do not have a secure password on your phone because you chose not to. The rest of us use finger print sensors or facial recognition to make our devices as secure as can be. Your argument applies only to you and a handful of people. Th…

Biometric phone security is only secure until a judge or police officer compels you to unlock your phone; and legally you must comply, because your face or finger aren't speech. However, if you use a passphrase, (at least in the US and other countries with string freedom of speech laws) you can't be legally compelled to unlock the phone, as that would impinge on freedom of speech. I never use biometrics to unlock my…

On iPhones you can press Volume Down + Power to disable biometrics (faceid) before you hand it to somebody else or when going through customs etc. It will require your passphrase to unlock then.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#60
post #58

Earlier quoted context omitted.

> Nobody has a secure password on their phone, so your requirement fails. > maybe finger prints, but I have found them unreliable and so I quit using them You mean that you specifically do not have a secure password on your phone because you chose not to. The rest of us use finger print sensors or facial recognition to make our devices as secure as can be. Your argument applies only to you and a handful of people. Th…

Biometric phone security is only secure until a judge or police officer compels you to unlock your phone; and legally you must comply, because your face or finger aren't speech. However, if you use a passphrase, (at least in the US and other countries with string freedom of speech laws) you can't be legally compelled to unlock the phone, as that would impinge on freedom of speech. I never use biometrics to unlock my…

That certainly is a case. Or they could torture and threaten you to give the password.

If this situation happens you can rapidly press the home button with the wrong finger and the phone will demand a pin code. Or you could turn it off. I don't know what recourse people with face unlock have.

Post reply on HN